Small job

Stopping spam in WordPress forms: reCAPTCHA, Turnstile and honeypots

We put the right spam protection (Turnstile, reCAPTCHA or honeypot) on your WordPress contact, registration and checkout forms, block bots and disposable e-mail addresses and clean out the existing spam, while real customers still get through.

  • Typical scope approx. 2 h
  • Roughly 100 € + VAT
  • Assessment and estimate are free

If your contact form delivers a dozen offers for SEO services and crypto investments every day, your WooCommerce shop keeps gaining customers who have never bought anything and some bot hammers wp-login.php all night, you have an ordinary WordPress spam problem. It wastes time, clutters the inbox and buries the real enquiries. In the worse cases, welcome e-mails sent to fake registrations also damage your domain’s sender reputation.

We put the right protection on each form, clean out the existing spam and check that real customers still get through. The aim is not the strictest possible lock but a balance: the bot stays outside, the human notices nothing.

What the work includes

  • Form review and choice of protection. We list every form on the site – contact, enquiry, registration, checkout, login, comments – and pick a suitable protection for each: Cloudflare Turnstile or Google reCAPTCHA v3 for visible forms, a honeypot field and a time check for low-friction forms, Akismet for comments.
  • Turnstile or reCAPTCHA set-up. We create the keys, connect them to your form plugin (Contact Form 7, WPForms, Gravity Forms, Fluent Forms or similar) and to WooCommerce, and make sure the script loads only on pages that have a form. Our default recommendation is Turnstile: it sends no visitor data to Google and is lighter on page speed.
  • Honeypot and time check. The form gets a field invisible to humans that bots fill in anyway, and we measure how quickly the form was submitted after the page loaded. Zero extra steps for the visitor.
  • WooCommerce registration, checkout and login. Protection on the My Account registration form, the checkout and wp-login.php. On the checkout we take particular care that the protection does not break payment or slow the purchase down.
  • Blocking disposable e-mail domains and bot patterns. Registrations with a disposable e-mail address are rejected. We also block the obvious patterns: messages consisting only of links, URLs in the name field, repeated attempts from the same IP.
  • Rate limiting. If the site sits behind Cloudflare, we set the login and checkout rules there; otherwise at the web server level (nginx limit_req, fail2ban) or with a login-attempt limiter plugin. We also close the XML-RPC interface if nothing uses it.
  • Cleaning out existing spam. We delete fake users with no orders, spam comments and spam orders. A backup is taken first and doubtful cases are reviewed with you.
  • Testing as a real customer. We submit the forms from a phone on a mobile network and from a different network, as a guest and logged in, to make sure the protection does not block people. Many mobile users share one IP address, so IP-based blocking has to stay lenient.
  • Cookie-consent compatibility. reCAPTCHA loads a Google script and sets cookies, so it has to work together with your cookie banner – otherwise a visitor who declined consent cannot submit the form at all. With Turnstile this side is simpler. Where needed we adjust the banner settings together with the cookie-consent set-up.

Typical situations

The contact form brings dozens of sales pitches a day and the one real enquiry gets lost among them. The WooCommerce shop has accumulated hundreds of users with random names and disposable addresses, none of whom has bought anything, and every new registration sends a welcome e-mail that drags down your e-mail deliverability. The checkout receives orders for a euro or two with strangers’ cards – a bot is testing stolen card numbers and the payment provider sends warnings. The blog holds thousands of unmoderated comments that nobody has searched for genuine ones in a long time. Or reCAPTCHA is already installed, but since the cookie banner was added some visitors can no longer submit the form.

What we need from you

  • WordPress administrator access and, where needed, access to the server or the Cloudflare account.
  • A Google or Cloudflare account for creating the keys – or we create them on your behalf.
  • A list of the forms that matter on the site and where the spam currently comes from.
  • A decision on whether suspicious users and comments can be deleted straight away or you want to review them first.
  • A day of attention after the work: if a real customer cannot submit a form, tell us immediately.

What is not included

  • Malware removal when the spam is caused by a hacked site (the site itself sends spam or foreign pages appear on it) – that is a separate job.
  • A broader security review of the server and the WordPress core.
  • Fixing e-mail deliverability (SPF, DKIM and DMARC records) – a separate service.
  • Ongoing monitoring and rule maintenance month after month – that belongs to monthly website maintenance.
  • Building a new form or installing a new form plugin.

Who it suits

It suits any WordPress site or WooCommerce shop where the forms, registration or comments are full of spam and you want it sorted in one go. If you suspect the site is also hacked or slow, start with the health and security audit instead, which checks the whole site at once; if you want someone to keep the rules and plugins in order going forward, monthly maintenance is the better fit.

approx. 2 h Typical scope
50 € Hourly rate + VAT
100 € Estimated total

This is an estimate, not a quote. We’ll review your site free of charge first and tell you the exact time required. If the job turns out smaller, you pay less – we bill for the time actually spent.

How this job works

  1. Send an enquiry

    Send us your site address and a couple of sentences about the problem. We usually reply the same or the next working day.

  2. We review it and give you the price

    The assessment is free. You’ll know the exact time and price before you decide on anything.

  3. We do the work and report back

    We take a backup before making changes. When the work is done you get a summary of exactly what was done and what to keep an eye on going forward.

Frequently asked questions

Which is better: Cloudflare Turnstile or Google reCAPTCHA?

In most cases we recommend Turnstile: it sends no visitor data to Google, is easier to reconcile with cookie consent and loads a lighter script. reCAPTCHA v3 makes sense if it is already in use or a plugin supports only that. We decide after the free review and estimate.

Will a captcha drive real customers away?

Turnstile and reCAPTCHA v3 usually show no challenge at all, and honeypots and time checks are completely invisible. After the set-up we test the forms from a phone and from a different network so that nobody is left outside.

Does the site have to be behind Cloudflare to use Turnstile?

No. Turnstile works as an independent key pair on any site; Cloudflare DNS or proxying is not required. Rate limiting with Cloudflare rules is only possible when the site is behind Cloudflare; otherwise we do it at the server level.

How much does it cost and how soon can you start?

The review and estimate are free and we bill by the actual time spent. We usually start within one to three working days and the work itself fits in one session; afterwards we keep an eye on it for a few days to confirm the spam has really stopped.

What if the spam continues after the work?

We check the logs to see where it comes from and tighten the rule where the bot gets through, for example by adding a time check or blocking a specific pattern. If the spam comes from the site itself, the site has been hacked and needs malware removal.

Testimonials

What our clients say

Long-standing partnerships say more than any slogan. Several of the clients below have been with us for over seven years.

We have worked with Birk for eight years now. This time we wanted a new website for the company, and the goals were set high from the very start – in visuals, functionality, manageability and SEO. Thanks to Birk’s professional approach we got a website of a high standard that met our expectations 100%. The collaboration went smoothly because Birk is a very good and direct communicator, helpful, dependable and conscientious.
Karina Riive Karina Riive LIGNAMETS OÜ, FARMLAND PURCHASING MANAGER
We ordered a feature-rich bespoke online store from Zezz. It was also important that it integrate with our accounting software. Zezz handled the task well and has been our day-to-day web development partner since 2018. Overall score 8/10 – there is always room to do better.
Aivo Kuldmeri Aivo Kuldmeri WESTBERG KAUBANDUS, MANAGING DIRECTOR
As a client you sometimes feel that you don’t know exactly how, and sometimes not even exactly what. But our collaboration has produced a website that our own people value and others try to copy. Thank you for the patience, the good ideas and the understanding. Thank you for visualising it and making it visible. I liked that Zezz keeps its word and stays flexible.
Mart Tilk Mart Tilk MANAGER, MÄRJAMAA SPORTS CENTRE

See our clients and testimonials

Get in touch

Let’s talk about your project

The first hour of consultation is free and comes with no obligation. We usually reply the same or the next working day.

  • The first hour is free – even if we don’t end up working together
  • You get a concrete price and timeline, not a vague “about”
  • No sales pressure and no automated follow-up calls

Request a quote

Describe what you need in a couple of sentences. We’ll get in touch and arrange a free consultation.


    Your details are never shared with third parties or used for newsletters.